9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
AI Analysis
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server
Basic Information
ID
CVE-2026-28780
Source
apache
Published
May 5, 2026 at 21:29
Modified
May 6, 2026 at 15:50
Affected Product
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Affected Versions
Apache Software Foundation Apache HTTP Server 0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Apache Foundation
Product
Apache HTTP Server
Version
through 2.4.66